First published: Sun Jul 17 2005(Updated: )
YabbSE 1.5.5c allows remote attackers to obtain sensitive information via a direct request to ssi_examples.php, which reveals the path.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Yabb | =1.5.5c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2005-2296 is considered medium due to its potential to expose sensitive path information.
To fix CVE-2005-2296, restrict access to the ssi_examples.php file or remove it entirely from the server.
CVE-2005-2296 is an information disclosure vulnerability that allows unauthorized access to system paths.
CVE-2005-2296 affects users of YaBB version 1.5.5c, particularly those running it without proper access restrictions.
Yes, CVE-2005-2296 can be exploited remotely by attackers who send direct requests to the vulnerable script.